01-27-2025 04:14 AM
Hi All
What are the recommended settings for MTU when using Anyconnect VPN?
We currently have the default of 1406.
We have users complaining of slow performance when using file shares, I know SMB is notoriously slow over WAN links etc, any recommendations if this can be sped up by setting a smaller MTU maybe? also we do not have the "ignore dont fragment bit" enabled.
Cheers
01-27-2025 04:44 AM
@carl_townshend I would leave the default MTU settings.
To get the best performance ensure you are using DTLS 1.2 for data communication, SSL/TLS should be used for the parent tunnel and backup in case DTLS is not functioning. You need to ensure your AnyConnect version supports DTLS, so it must be AnyConnect 4.7 or higher.
01-27-2025 04:49 AM
Hi Rob, thanks for the response, we do have DTLS enabled and on a recent version of Anyconnect.
These are pretty much our settings, any changes needed then or is this OK ?
01-27-2025 04:52 AM
@carl_townshend run show vpn-sessiondb detail anyconnect and check the output of a connection that is slow, confirm DTLS 1.2 is in use. https://integratingit.wordpress.com/2021/01/27/securing-asa-tls-ciphers/
01-27-2025 04:54 AM
Multi points to solve slow of anyconnect
1- using dtls
2- use correct mtu
3- split tunnel
For mtu check this
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide